For compliance offices · Costa Rica

Your due diligence policy is already written. Who runs it every day?

The complete documentary matrix for Costa Rica's regulated entities, with the templates to operate it from day one. Built article by article on Ley 7786, Reglamento 36948 and Acuerdos CONASSIF 12-21 and 11-21 and Acuerdo SUGEF 13-19.

One payment. Immediate download. No subscription.

Document matrix

v1.0
  • Know Your Customer form DDCR-P01
  • Documentary checklists DDCR-P02
  • Documentary checklists · Excel DDCR-P02B
  • Client knowledge file note DDCR-P03
  • Client declarations DDCR-P04

Traffic light by diligence type, with the article behind it

The problem

Three things that fail silently

We find them in almost every compliance office, whatever the size of the entity. None of them surfaces on the day it happens.

Documents that expire with no warning

A digital company registration certificate from the Registro Nacional is valid for fifteen calendar days. A notarised share capital certificate, one month under Acuerdo 12-21. Nobody looks at those dates until the supervisor's visit.

Evidence the regulation does not accept

Acuerdo CONASSIF 11-21 set a closed catalogue of documents that evidence the source of funds, and expressly excluded bank statements, sworn declarations — even notarised — and transfer receipts. They keep going into files because they «show something».

Every account executive reads the policy their own way

They ask a low-risk salaried client for documents simplified diligence does not require, and skip the capital certificate for a company because «they already brought the registration». The file comes back, the client waits, the officer reworks it.

The cost is not only regulatory. It is the officer's time, friction with the client, and commercial growth stuck in the compliance queue.

The matrix

One single documentary source of truth

Four cross-referenced tables that answer, for any client, what to ask for, what to accept, when it expires and which article requires it.

7

types of due diligence

Simplified, standard for individuals and for legal entities, enhanced, foreign legal entity, trusts and structures, and third parties. Assigned by a decision tree of six questions in order.

37

documentary rules

Every document with its marking per diligence type — required, conditional, optional or not applicable — and the article that supports it.

23

source-of-funds evidence items

The closed catalogue of Acuerdo CONASSIF 11-21, organised by category, with each document's maximum age and the list of what is not accepted.

19

document classes

Each class with a single expiry rule, its alert window and whether an attachment is required. This is what stops anything expiring silently.

Built on Ley 7786, Decreto Ejecutivo 36948, Acuerdos CONASSIF 12-21 and 11-21, Acuerdo SUGEF 13-19, the INTE/ISO 37301:2021 standard and the OECD Due Diligence Guidance.

What is included

What you download, file by file

A matrix is worth little if the team cannot operate it. These are the templates that go with it, grouped the way they are used.

Matrix, guide and presentation

3 files

  • Due Diligence Matrix
  • Matrix Guide · Legal Design edition
  • Executive presentation

Client file

7 files

  • Know Your Customer form
  • Documentary checklists
  • Documentary checklists · Excel
  • Client knowledge file note
  • Client declarations
  • Senior management approval minutes
  • On-site verification report

Governance and policy

2 files

  • Due diligence documentation policy
  • Parameter approval minutes

Control and monitoring

5 files

  • Client risk matrix
  • Version and regulatory change log
  • Document expiry dashboard
  • Annual update plan
  • Pre-supervision self-assessment

Third parties and client communication

2 files

  • Third-party due diligence questionnaire
  • Document request and renewal letters

Team training

1 files

  • Internal training module

How it is written

Legal Design applied to compliance

A document nobody understands is not a control: it is paper. The whole package follows the same drafting principles.

  • The rule in one sentence, then what to do, then the legal basis.

  • Every acronym and technical term explained inline: PEP, CICAC, RTBF, beneficial owner, apostille.

  • Editable fields in pale yellow and proposed parameters in blue, so what has to be decided is visible at a glance.

  • «Careful» boxes where the mistake is common, and «Good practice» boxes where it is worth going further.

What it is NOT

  • It does not replace your internal policy. It is the complete, traceable base to build or review one; the parameters Acuerdo CONASSIF 12-21 leaves to each entity still have to be decided and motivated in minutes.
  • It is not legal advice. It is reference material prepared on the regulation in force, which each entity must validate with its compliance officer and its counsel.
  • It does not include every superintendency's guidelines. The ones included are SUGEF's; entities under SUGEVAL, SUGESE or SUPEN must check their own, as article 4 of Acuerdo 12-21 requires.

Price

One payment, and it is yours

No subscription, no per-user licences, no renewal.

USD 97

One-off payment, taxes according to your jurisdiction

  • The complete files, editable and without watermarks.
  • Unlimited internal use across your entity and its subsidiaries.
  • Immediate download, as many times as you need.
  • The guides and the presentation in PDF, ready to circulate.
  • Electronic invoice with your tax details.
Get the toolkit

If the package is not what you expected, write to us within the first fourteen days.

Questions

What people ask before buying

Which regulations, laws and good practices were used to build these tools?

Seven sources, reviewed article by article. FIVE are legally binding in Costa Rica: Ley 7786 and its regulation, Decreto Ejecutivo 36948, which define who is a regulated entity and what their duties are; Acuerdo CONASSIF 12-21, which governs the entities of article 14; Acuerdo CONASSIF 11-21, which sets the closed catalogue of source-of-funds evidence and the use of the CICAC; and Acuerdo SUGEF 13-19, which governs those registered under articles 15 and 15 bis. The other TWO are good practice and not Costa Rican regulatory requirements: the INTE/ISO 37301:2021 compliance management systems standard, which is where the controls over outsourced processes, the monitoring and the internal audit come from; and the OECD Due Diligence Guidance, which is where the six-stage third-party model comes from. Every rule in the package names the article that supports it, so it can be verified at source.

Which entities does this matrix apply to?

If you are a regulated entity under article 14 of Ley 7786 — supervised by SUGEF, SUGEVAL, SUGESE or SUPEN — the Acuerdo CONASSIF 12-21 regime applies. If you are registered under articles 15 or 15 bis, Acuerdo SUGEF 13-19 applies. The matrix covers both regimes and its parameters sheet compares them side by side.

Does it replace our internal policy?

No. It is a complete, traceable base to build or review one. The parameters that Acuerdo CONASSIF 12-21 leaves to the entity's judgement — frequencies, alerts, exemptions — have to be decided and motivated in minutes, and one of the templates exists exactly for that.

Why does a bank statement not count as source of funds?

Because Acuerdo CONASSIF 11-21, in its Section II, expressly excludes it. A bank statement shows movements, not the source that generates them. The package includes the full catalogue of what is accepted, with each item's maximum age, and a plain-language page to explain it to the client.

How often does a client have to be updated?

Under Acuerdo CONASSIF 12-21 each entity's own policy decides, based on risk, with a ceiling of sixty months and a higher frequency for high risk. Under Acuerdo SUGEF 13-19 the deadlines are fixed. Many policies still copy the fixed deadlines with no minutes to justify them, and that is a finding however reasonable the deadlines are.

Can I accept the RTBF declaration instead of the notarised capital certificate?

Yes, under article 34 of Acuerdo CONASSIF 12-21, stamped by the Central Bank and issued no more than thirty days earlier. It is free, and most entities still do not accept it.

Are the templates editable?

The tools are: Word, Excel and PowerPoint, with no macros. The guides and the presentation are PDF on purpose, because they are reference material and are not built to be altered.

Is it useful if my entity already has an approved policy?

Yes, and that is the most common use. The matrix lets you check your current policy rule by rule against the regulation, and the pre-supervision self-assessment — thirty questions with the evidence expected for each — shows where the support is missing before the supervisor finds it.

Is it up to date?

The package was prepared on Costa Rican regulation in force as of September 2026, and includes a version and regulatory change log to record every review. Regulation changes: the cut-off date is written into every file.

Stop holding the policy together with your team's memory

Download the matrix, approve your parameters in minutes and hand out the templates. What lives today in the compliance officer's head becomes written down, with the article behind every rule.

Get the toolkit · USD 97

And if this ran by itself?

A perfect matrix is still a document: somebody has to read it, remember it and apply it, client by client. Snap Compliance's ERP for Risk Management and Regulatory Compliance turns these same rules into a system that assigns the diligence type, validates the evidence, calculates the risk and warns before anything expires.

See the Snap Compliance ERP